A discrete cosine transform-based query efficient attack on black-box object detectors

Xiaohui Kuang,Xianfeng Gao,Lianfang Wang,Gang Zhao,Lishan Ke,Quanxin Zhang
DOI: https://doi.org/10.1016/j.ins.2020.05.089
IF: 8.1
2021-01-01
Information Sciences
Abstract:Deep learning models are being widely used in almost every field of computing and information processing. The advantages offered by these models are unparalleled, however, similar to any other computing discipline, they are also vulnerable to security threats. compromised deep neural network can significantly impact its robustness and accuracy. In this work, we present a novel targeted attack method against state-of-the-art object detection models YOLO v3 and AWS Rekognition in a black-box environment. We present an improved attack method using Discrete Cosine Transform based on boundary attack plus plus mechanism, and apply it on attacking object detectors offline and online. querying the victim detection models along with transforming the images from the spatial domain into the frequency domain, we ensure that any specified object in an image can successfully recognized as any other desired class by YOLO v3 and AWS Rekognition. The results prove that our method has significant boosting effects on boundary attacks in offline and online object detection systems. (c) 2020 Elsevier Inc. All rights reserved.
What problem does this paper attempt to address?